Real-world descriptions of how a group, tool or campaign used a technique.
95 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.001 Local Data Staging |
MalwareExaramel for Windows | Exaramel for Windows specifies a path to store files scheduled for exfiltration. |
| T1074.001 Local Data Staging |
MalwareNOKKI | NOKKI can collect data from the victim and stage it in |
| T1074.001 Local Data Staging |
MalwareKOPILUWAK | KOPILUWAK has piped the results from executed C2 commands to `%TEMP%\result2.dat` on the local machine. |
| T1074.001 Local Data Staging |
MalwareVersaMem | VersaMem staged captured credentials locally at `/tmp/.temp.data`. |
| T1074.001 Local Data Staging |
MalwarePAKLOG | PAKLOG has stored the captured data in a file located `C:\\Users\\Public\\Libraries\\record.txt`. |
| T1074.001 Local Data Staging |
MalwareUrsnif | Ursnif has used tmp files to stage gathered information. |
| T1074.001 Local Data Staging |
MalwareFrameworkPOS | FrameworkPOS can identifiy payment card track data on the victim and copy it to a local file in a subdirectory of C:\Windows\. |
| T1074.001 Local Data Staging |
MalwareInvisibleFerret | InvisibleFerret has staged data in consolidated folders prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareRainyDay | RainyDay can use a file exfiltration tool to copy files to |
| T1074.001 Local Data Staging |
MalwareAppleSeed | AppleSeed can stage files in a central location prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareNETWIRE | NETWIRE has the ability to write collected data to a file created in the |
| T1074.001 Local Data Staging |
MalwareMirrorStealer | MirrorStealer has stored stolen credentials on the local machine in `%TEMP%\31558.txt`. |
| T1074.001 Local Data Staging |
MalwareTurian | Turian can store copied files in a specific directory prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareMachete | Machete stores files and logs in a folder on the local drive. |
| T1074.001 Local Data Staging |
MalwarePowerLess | PowerLess can stage stolen browser data in `C:\\Windows\\Temp\\cup.tmp` and keylogger data in `C:\\Windows\\Temp\\Report.06E17A5A-7325-4325-8E5D-E172EBA7FC5BK`. |
| T1074.001 Local Data Staging |
MalwarePrikormka | Prikormka creates a directory, |
| T1074.001 Local Data Staging |
MalwareMafalda | Mafalda can place retrieved files into a destination directory. |
| T1074.001 Local Data Staging |
MalwareAuTo Stealer | AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareSombRAT | SombRAT can store harvested data in a custom database under the %TEMP% directory. |
| T1074.001 Local Data Staging |
MalwareFLASHFLOOD | FLASHFLOOD stages data it copies from the local system or removable drives in the "%WINDIR%\$NtUninstallKB885884$\" directory. |
| T1074.001 Local Data Staging |
MalwareLoFiSe | LoFiSe can save files to be evaluated for further exfiltration in the `C:\Programdata\Microsoft\` and `C:\windows\temp\` folders. |
| T1074.001 Local Data Staging |
MalwareCuckoo Stealer | Cuckoo Stealer has staged collected application data from Safari, Notes, and Keychain to `/var/folder`. |
| T1074.001 Local Data Staging |
MalwareInvisiMole | InvisiMole determines a working directory where it stores all the gathered data about the compromised machine. |
| T1074.001 Local Data Staging |
MalwareMarkiRAT | MarkiRAT can store collected data locally in a created .nfo file. |
| T1074.001 Local Data Staging |
MalwareKazuar | Kazuar stages command output and collected data in files before exfiltration. |
| T1074.001 Local Data Staging |
MalwareNavRAT | NavRAT writes multiple outputs to a TMP file using the >> method. |
| T1074.001 Local Data Staging |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value. |
| T1074.001 Local Data Staging |
MalwareChrommme | Chrommme can store captured system information locally prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareObliqueRAT | ObliqueRAT can copy specific files, webcam captures, and screenshots to local directories. |
| T1074.001 Local Data Staging |
MalwareSocGholish | SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`. |
| T1074.001 Local Data Staging |
MalwarePUNCHBUGGY | PUNCHBUGGY has saved information to a random temp file before exfil. |
| T1074.001 Local Data Staging |
MalwarePteranodon | Pteranodon creates various subdirectories under |
| T1074.001 Local Data Staging |
MalwareBeaverTail | BeaverTail has staged collected data to the system’s temporary directory. |
| T1074.001 Local Data Staging |
MalwareDarkWatchman | DarkWatchman can stage local data in the Windows Registry. |
| T1074.001 Local Data Staging |
MalwareDyre | Dyre has the ability to create files in a TEMP folder to act as a database to store information. |
| T1074.001 Local Data Staging |
MalwarePACEMAKER | PACEMAKER has written extracted data to `tmp/dsserver-check.statementcounters`. |
| T1074.001 Local Data Staging |
MalwarePlugX | PlugX has collected and staged the victim’s computer files for exfiltration. |
| T1074.001 Local Data Staging |
MalwareLumma Stealer | Lumma Stealer has configured a custom user data directory such as a folder within `%USERPROFILE%\AppData\Roaming` for staging data. |
| T1074.001 Local Data Staging |
MalwareDustySky | DustySky created folders in temp directories to host collected files before exfiltration. |
| T1074.001 Local Data Staging |
MalwareRover | Rover copies files from removable drives to |
| T1074.001 Local Data Staging |
MalwareLightNeuron | LightNeuron can store email data in files and directories specified in its configuration, such as |
| T1074.001 Local Data Staging |
MalwareElise | Elise creates a file in |
| T1074.001 Local Data Staging |
MalwareLODEINFO | LODEINFO has collected stolen web cookies locally in the `%TEMP%` folder. |
| T1074.001 Local Data Staging |
MalwareSagerunex | Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution. |
| T1074.001 Local Data Staging |
MalwareLP-Notes | LP-Notes has stored collected credentials in ` C:\Users\Public\Downloads\lp-notes.txt`. |
| T1074.001 Local Data Staging |
MalwareGlassWorm | GlassWorm has staged collected data in a working directory within a temp folder to include `/tmp/ijewf`. |
| T1074.001 Local Data Staging |
MalwareTrojan.Karagany | Trojan.Karagany can create directories to store plugin output and stage data for exfiltration. |
| T1074.001 Local Data Staging |
MalwareSPACESHIP | SPACESHIP identifies files with certain extensions and copies them to a directory in the user's profile. |
| T1074.001 Local Data Staging |
MalwareKGH_SPY | KGH_SPY can save collected system information to a file named "info" before exfiltration. |
| T1074.001 Local Data Staging |
MalwareCatchamas | Catchamas stores the gathered data from the machine in .db files and .bmp files under four separate locations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.